cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Join Customer Connection to register!
623
Views
0
Helpful
3
Replies
Jeff Horton
Beginner

MACsec vs IPsec/GRE

Does the MACsec sufficiently encrypt data (multicast, .etc) on the Cisco 9000 series switch so that I don't have to worry about deploying GRE/IPsec?

 

Thoughts?

 

 

1 ACCEPTED SOLUTION

Accepted Solutions
Reza Sharifi
Hall of Fame Expert

GRE/IPsec is usually used for connecting multiple sites together over the Internet (WAN connection). On the other hand, MACsec is for host to switch encryption or between switches. So, two different functions.

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/sec/b_166_sec_9300_cg/macsec_encryption.html

HTH 

 

View solution in original post

3 REPLIES 3
Reza Sharifi
Hall of Fame Expert

GRE/IPsec is usually used for connecting multiple sites together over the Internet (WAN connection). On the other hand, MACsec is for host to switch encryption or between switches. So, two different functions.

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/sec/b_166_sec_9300_cg/macsec_encryption.html

HTH 

 

View solution in original post

So if I read correctly what you are saying, then MACsec would be good for the switch to switch connection and no need for GRE/IPsec?

So if I read correctly what you are saying, then MACsec would be good for the switch to switch connection and no need for GRE/IPsec?

That is correct.

HTH